<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>N8n (&lt; 1.123.76) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/n8n--1.123.76/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 18:53:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/n8n--1.123.76/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Domain-Restriction Bypass in n8n OpenAI Chat Model Node</title><link>https://feed.craftedsignal.io/briefs/2026-09-n8n-domain-bypass/</link><pubDate>Thu, 10 Sep 2026 18:53:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-n8n-domain-bypass/</guid><description>An unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.</description><content:encoded><![CDATA[<p>A security vulnerability in n8n (CVE-2026-86082) allows authenticated users to bypass configured domain restrictions within the OpenAI Chat Model node. While the primary OpenAI request path correctly validated custom base URLs against allowed-domain configurations, the secondary model-search dropdown endpoint failed to perform this check. An attacker able to manipulate request options could define a custom base URL that directed sensitive requests to an arbitrary, attacker-controlled host while still including the original, valid OpenAI credentials. This flaw enables the exfiltration of API keys or the use of credentials against unauthorized third-party infrastructure. This vulnerability affects multiple versions of n8n across the 1.x and 2.x branches and necessitates a prompt upgrade to the patched versions to ensure consistent credential protection across all API call sites.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized use of OpenAI credentials by routing requests to external hosts, potentially leading to credential exposure or unauthorized usage of services. If compromised, an attacker can leverage these credentials to make unauthorized API calls. Security teams should assume any n8n instance with domain-restricted OpenAI credentials might have been subject to credential exposure if the instance was accessible to untrusted users prior to patching.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade n8n to version 1.123.76, 2.37.7, 2.38.2, or later to implement centralized domain validation for all OpenAI call sites.</li>
<li>Rotate all OpenAI API keys currently stored in n8n instances if there is suspicion of unauthorized access or exposure via this vector.</li>
<li>Review OpenAI account usage logs for any traffic originating from unexpected or unauthorized endpoints.</li>
<li>Restrict access to the n8n instance to trusted users until the software is patched.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>webserver</category><category>credential-theft</category><category>n8n</category><category>cve-2026-86082</category><category>denial-of-service</category><category>web-vulnerability</category><category>cve-2026-86076</category><category>javascript</category><category>sandbox-escape</category></item></channel></rss>